[Qgis-user] help - Question regarding QGIS and Microsoft ASR rule "Block use of copied or impersonated system tools"
Sondre Een Kvalfoss
sondre.e.kvalfoss at voss.herad.no
Tue Sep 1 06:27:46 PDT 2026
Hello,
We have recently enabled a new Microsoft Defender Attack Surface Reduction (ASR) rule in our environment called "Block use of copied or impersonated system tools", currently running in Audit mode.
During our review of the audit logs, we have observed events involving curl.exe and the source application powershell.exe, where the common factor appears to be the following QGIS installation path:
C:\Program Files\QGIS 4.2.1\bin
Before enabling this ASR rule in Block mode, we would appreciate your help in understanding what is triggering these events and how QGIS uses these components. Our goal is to determine whether this behavior is expected and whether it would be appropriate to create an exclusion for QGIS if necessary.
Could you please provide any details on the processes or functionality within QGIS that may invoke curl.exe and/or powershell.exe from this location?
Thank you for your assistance. Please include me in the reply if possible.
Kind regards,
Sondre Een Kvalfoss
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.osgeo.org/pipermail/qgis-user/attachments/20260901/519a490c/attachment.htm>
More information about the QGIS-User
mailing list